Information Disclosure Vulnerability in Microsoft Office Word
CVE-2026-40421
4.3MEDIUM
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40421?
An information disclosure vulnerability in Microsoft Office Word allows unauthorized attackers to control file names or paths. This could enable attackers to disclose sensitive information over a network, potentially compromising user data. It is crucial for users to apply the latest updates to mitigate the risk associated with this vulnerability.
Affected Version(s)
Microsoft 365 Apps for Enterprise 32-bit Systems 16.0.1
Microsoft Office 2019 32-bit Systems 19.0.0
Microsoft Office LTSC 2021 32-bit Systems 16.0.1